US2025384125A1PendingUtilityA1
Secure system automated design device, secure system automated design method, and storage medium
Est. expiryJun 14, 2044(~17.9 yrs left)· nominal 20-yr term from priority
Inventors:Ryosuke Hotchi
G06F 2221/034G06F 21/552
65
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A secure system automated design device accepts a design requirement of a system; generates a system configuration plan that satisfies the design requirement; derives threats that are present in the system configuration plan, attack paths that are constituted by a chain of the threats, and countermeasures that are implemented with respect to the threats; and derives a threat consideration priority that represents a priority with which the threats are to be considered, and an attack path consideration priority that represents a priority with which the attack paths are to be considered.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A secure system automated design device comprising:
at least one memory configured to store instructions; and at least one processor configured to execute the instructions to:
accept a design requirement of a system;
generate a system configuration plan that satisfies the design requirement;
derive threats that are present in the system configuration plan, attack paths that are constituted by a chain of the threats, and countermeasures that are implemented with respect to the threats; and
derive a threat consideration priority that represents a priority with which the threats are to be considered, and an attack path consideration priority that represents a priority with which the attack paths are to be considered.
2 . The secure system automated design device according to claim 1 , wherein the at least one processor is configured to execute the instructions to:
derive the attack path consideration priority for all of the threats that are present in the system configuration plan by referring to security model information; and derive the attack path consideration priority for all of the attack paths based on information about the threats and the countermeasure that is present in the system configuration plan.
3 . The secure system automated design device according to claim 1 , wherein the at least one processor is configured to execute the instructions to:
derive the attack path consideration priority for all of the threats that are present in the system configuration plan by referring to security model information, while also deriving a threat concretization relationship consideration priority that represents a priority with which a relationship between the threats is to be considered; and derive the attack path consideration priority for all of the attack paths based on information about the threats, the countermeasures, and the relationships between the threats that is present in the system configuration plan.
4 . The secure system automated design device according to claim 1 , wherein the at least one processor is configured to execute the instructions to:
accept a tolerance value of a security of the system; compare the attack path consideration priority for each attack path and the tolerance value; and determine that the system configuration plan is not unsecure if all of the attack path consideration priorities are less than the tolerance value.
5 . The secure system automated design device according to claim 4 , wherein the at least one processor is configured to execute the instructions to:
compare the attack path consideration priority of each attack path with the tolerance value; and do not derive the countermeasure for an attack path in which the attack path consideration priority is less than the tolerance value.
6 . The secure system automated design device according to claim 2 , wherein the at least one processor is configured to execute the instructions to:
derive the attack path consideration priority by multiplying the threat consideration priority derived for all of the threats constituting the attack path; and set the threat consideration priority of the threats for which a countermeasure has been derived to a value lower than an attack path threshold.
7 . The secure system automated design device according to claim 3 , wherein the at least one processor is configured to execute the instructions to:
derive the attack path consideration priority by multiplying the threat consideration priority derived for all of the threats constituting the attack path, and a threat concretization relationship consideration priority derived for the relationships between all of the threats constituting the attack path; and set the threat consideration priority of the threats for which a countermeasure has been derived to a value lower than an attack path threshold.
8 . A secure system automated design method that causes a secure system automated design device to perform:
accepting a design requirement of a system; generating a system configuration plan that satisfies the design requirement; deriving threats that are present in the system configuration plan, attack paths constituted by a chain of the threats, and countermeasures that are implemented with respect to the threats; and deriving a threat consideration priority that represents a priority with which the threats are to be considered, and an attack path that are consideration priority that represents a priority with which the attack paths are to be considered.
9 . The secure system automated design method according to claim 8 , further comprising:
deriving the attack path consideration priority for all of the threats that are present in the system configuration plan by referring to security model information; and deriving the attack path consideration priority for all of the attack paths based on information about the threats and the countermeasure that is present in the system configuration plan.
10 . The secure system automated design method according to claim 8 , further comprising:
deriving the attack path consideration priority for all of the threats that are present in the system configuration plan by referring to security model information, while also deriving a threat concretization relationship consideration priority that represents a priority with which a relationship between the threats is to be considered; and deriving the attack path consideration priority for all of the attack paths based on information about the threats, the countermeasures, and the relationships between the threats that is present in the system configuration plan.
11 . The secure system automated design method according to claim 8 , further comprising:
accepting a tolerance value of a security of the system; comparing the attack path consideration priority for each attack path and the tolerance value; and determining that the system configuration plan is not unsecure if all of the attack path consideration priorities are less than the tolerance value.
12 . The secure system automated design method according to claim 11 , further comprising:
comparing the attack path consideration priority of each attack path with the tolerance value; and doing not derive the countermeasure for an attack path in which the attack path consideration priority is less than the tolerance value.
13 . The secure system automated design method according to claim 9 , further comprising:
deriving the attack path consideration priority by multiplying the threat consideration priority derived for all of the threats constituting the attack path; and setting the threat consideration priority of the threats for which a countermeasure has been derived to a value lower than an attack path threshold.
14 . The secure system automated design method according to claim 10 , further comprising:
deriving the attack path consideration priority by multiplying the threat consideration priority derived for all of the threats constituting the attack path, and a threat concretization relationship consideration priority derived for the relationships between all of the threats constituting the attack path; and setting the threat consideration priority of the threats for which a countermeasure has been derived to a value lower than an attack path threshold.
15 . A non-transitory storage medium storing a program that causes a computer to execute:
accepting a design requirement of a system; generating a system configuration plan that satisfies the design requirement; deriving threats that are present in the system configuration plan, attack paths that are constituted by a chain of the threats, and countermeasures that are implemented with respect to the threats; and deriving a threat consideration priority that represents a priority with which the threats are to be considered, and an attack path consideration priority that represents a priority with which the attack paths are to be considered.Join the waitlist — get patent alerts
Track US2025384125A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.